cbcvebase.
CVE-2025-40161
published 2025-11-12

CVE-2025-40161: In the Linux kernel, the following vulnerability has been resolved: mailbox: zynqmp-ipi: Fix SGI cleanup on unbind The driver incorrectly determines SGI vs SPI…

PriorityP420
EPSS
0.18%
8.2th percentile
In the Linux kernel, the following vulnerability has been resolved: mailbox: zynqmp-ipi: Fix SGI cleanup on unbind The driver incorrectly determines SGI vs SPI interrupts by checking IRQ number < 16, which fails with dynamic IRQ allocation. During unbind, this causes improper SGI cleanup leading to kernel crash. Add explicit irq_type field to pdata for reliable identification of SGI interrupts (type-2) and only clean up SGI resources when appropriate.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.6-1 (forky)linux 6.17.6-1 (forky)
linuxlinux
linuxlinux>= 6ffb1635341bec50fa9540ae7827d1e5d75ae0b0 < 1ee147efee68be00203b1fee6479911debb1edb21ee147efee68be00203b1fee6479911debb1edb2
linuxlinux>= 6ffb1635341bec50fa9540ae7827d1e5d75ae0b0 < 32bf7c6e01f5ba17a53ba236a770bd0274cefdf432bf7c6e01f5ba17a53ba236a770bd0274cefdf4
linuxlinux>= 6ffb1635341bec50fa9540ae7827d1e5d75ae0b0 < bb160e791ab15b89188a7a19589b8e11f681bef3bb160e791ab15b89188a7a19589b8e11f681bef3
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.10.0 < 6.12.546.12.54
linuxlinux_kernel>= 6.13.0 < 6.17.46.17.4
ubuntulinux-aws
ubuntulinux-oracle
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.